Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesHard

A security architect is designing a new network segment for highly sensitive financial data. They propose implementing a firewall at the perimeter, intrusion detection systems (IDS) within the segment, and host-based firewalls on individual servers, alongside strong access controls and encryption. Which overarching security strategy is being applied here?

  1. ADefense in Depth
  2. BSecurity by Obscurity
  3. CZero Trust Architecture
  4. DPrinciple of Least Privilege
Show answer & explanation

Correct answer: A. Defense in Depth

The architect is proposing multiple layers of security controls (firewall, IDS, host-based firewalls, access controls, encryption) to protect the sensitive data. This layered approach is the definition of Defense in Depth.

Why the other options are wrong

  • B. Security by Obscurity relies on hiding information, which is a weak and generally ineffective security approach, not what's described.
  • C. Zero Trust assumes no implicit trust, even inside the network, and verifies every access request, but is a more specific implementation detail than the broad strategy of layering controls.
  • D. Least Privilege grants minimum necessary access, which is a component of access control, but not the overarching strategy of layering multiple protections.

Defense in Depth

A cybersecurity strategy that employs multiple layers of security controls to protect information and systems. The idea is that if one layer of defense is breached, another layer will be in place to prevent or detect further unauthorized access.

  • Based on military strategy of layered fortifications.
  • Combines administrative, technical, and physical controls.
  • Aims to slow down attackers and provide multiple detection points.

Memory trick: Defense in Depth is like an onion: many layers protect the core.

More Security Principles questions